
Kin Visitantes Security & Risk Analysis
wordpress.org/plugins/kin-visitantesTrack visitors to your website easily and effectively.
Is Kin Visitantes Safe to Use in 2026?
Generally Safe
Score 85/100Kin Visitantes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "kin-visitantes" v2.4 exhibits a mixed security posture. On one hand, the static analysis reveals a very small attack surface with no detected AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all SQL queries are reported as using prepared statements, and there are no file operations or external HTTP requests, which are positive signs. However, a significant concern arises from the output escaping results: 100% of the 18 analyzed outputs are not properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data displayed on the front-end or back-end might not be neutralized, allowing malicious scripts to be injected and executed.
The taint analysis, while reporting no critical or high severity flows, does identify 3 flows with unsanitized paths. Although the severity isn't explicitly stated as critical, unsanitized paths can often lead to security issues if not handled correctly, especially when combined with the lack of output escaping. The vulnerability history is currently clean, with no recorded CVEs, which is a positive indicator of the plugin's past security. However, the absence of past vulnerabilities does not guarantee future security, especially given the identified output escaping and unsanitized path issues.
In conclusion, while "kin-visitantes" v2.4 has strengths in its limited attack surface and secure SQL practices, the complete lack of output escaping for all analyzed outputs presents a critical security weakness. This, coupled with the presence of unsanitized paths, creates a substantial risk of XSS attacks. The plugin's clean vulnerability history is a good sign, but it should not overshadow the immediate concerns identified in the static analysis.
Key Concerns
- Unescaped output on all analyzed outputs
- Taint flows with unsanitized paths
Kin Visitantes Security Vulnerabilities
Kin Visitantes Code Analysis
Output Escaping
Data Flow Analysis
Kin Visitantes Attack Surface
WordPress Hooks 3
Maintenance & Trust
Kin Visitantes Maintenance & Trust
Maintenance Signals
Community Trust
Kin Visitantes Alternatives
Connect Matomo – Analytics Dashboard for WordPress
wp-piwik
Adds Matomo (former Piwik) statistics to your WordPress dashboard and is also able to add the Matomo Tracking Code to your blog.
User Activity Tracking and Log
user-activity-tracking-and-log
Track time and monitor user activity & history on your website, LMS online learning system, membership or WooCommerce site.
Trace My IP – Visitor IP Tracker, Stats Analytics & Page Views Counter with Email Alerts
tracemyip-visitor-analytics-ip-tracking-control
Comprehensive visitor IP tracking and website analytics solution with real-time statistics, page view counting, and customizable email alerts.
Stetic
stetic
Web Analytics from Stetic including many features. Displays a widget, a complete analytics dashboard page and adds the tracking code to your site.
Simple Webstats
simple-webstats
Privacy-focused cookie-free web analytics for WordPress.
Kin Visitantes Developer Profile
1 plugin · 10 total installs
How We Detect Kin Visitantes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kin-visitantes/js/kin-visitantes.js/wp-content/plugins/kin-visitantes/css/kin-visitantes.csshttps://www.google.com/jsapikin-visitantes/js/kin-visitantes.js?ver=kin-visitantes/css/kin-visitantes.css?ver=HTML / DOM Fingerprints
mc-field-groupmc-embedded-subscribe-formmc-embedded-subscribemc-embed-signup<!--
_ _______ _ _ __ ________ ____ _____ ______ _____ _____ _____ _ _
| |/ /_ _| \ | | \ \ / / ____| _ \ | __ \| ____|/ ____|_ _/ ____| \ | |
| ' / | | | \| | \ \ /\ / /| |__ | |_) | | | | | |__ | (___ | || | __| \| |
| < | | | . ` | \ \/ \/ / | __| | _ < | | | | __| \___ \ | || | |_ | . ` |
| . \ _| |_| |\ | \ /\ / | |____| |_) | | |__| | |____ ____) |_| || |__| | |\ |
|_|\_\_____|_| \_| \/ \/ |______|____/ |_____|______|_____/|____\_____|_| \_|
-->id="chart_div"name="ignored_ip"name="FNAME"name="LNAME"name="EMAIL"id="mce-FNAME"+7 moregoogle.loadgoogle.setOnLoadCallbackdrawChartgoogle.visualization.arrayToDataTablegoogle.visualization.AreaChartnew google.visualization.AreaChart